Splunk Search

Display only a particular key

Path Finder


Can someone help me with the splunk query where i need to display only eapply as the key

...|eval key=mvindex(split(nbamboo_buildkey,"="),1) | table key

it displays all the bamboo_buildkey along with eapply, repository number, etc 

Labels (5)
Tags (1)
0 Karma


Will this work?

...|eval key=mvindex(split(nbamboo_buildkey,"="),1) 
| where key="eapply"
| table key
0 Karma


Hi @Nith1,

Can you please give a sample event for nbamboo_buildkey for us to help?

If this reply helps you an upvote is appreciated.
0 Karma
Get Updates on the Splunk Community!

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Want a chance to win $500 to the Splunk shop? Take our IT Incident Management Survey!

  Top Trends & Best Practices in Incident ManagementSplunk is partnering up with Constellation Research to ...